CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2024-27360

    Last Modified: 27 Aug 2025

    A vulnerability was discovered in Samsung Mobile Processors Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, and Exynos W930 where they do not properly check length of the data, which can lead to a Denial of Service.

    Published: 9 Jul 2024
    5.3
    Medium

    CVE-2024-28068

    Last Modified: 26 Jun 2025

    A vulnerability was discovered in SS in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, and Exynos Modem 5300 that involves a NULL pointer dereference which can cause abnormal termination of a mobile phone via a manipulated packet.

    Published: 9 Jul 2024
    8.1
    High

    CVE-2024-29153

    Last Modified: 26 Jun 2025

    A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, and Exynos Modem 5300 that involves incorrect authorization of LTE NAS messages and leads to downgrading to lower network generations and repeated DDOS.

    Published: 9 Jul 2024
    7.5
    High

    CVE-2024-6604

    Last Modified: 30 Oct 2025

    Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

    Published: 9 Jul 2024
    8.4
    High

    CVE-2023-50806

    Last Modified: 26 Jun 2025

    A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850 Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380 Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123, Exynos Modem 5300 that allows out-of-bounds access to a heap buffer in the SIM Proactive Command.

    Published: 9 Jul 2024
    8.1
    High

    CVE-2023-50807

    Last Modified: 26 Jun 2025

    A vulnerability was discovered in Samsung Wearable Processor and Modems with versions Exynos 9110, Exynos Modem 5123, Exynos Modem 5300 that allows an out-of-bounds write in the heap in 2G (no auth).

    Published: 9 Jul 2024
    5.1
    Medium

    CVE-2024-27361

    Last Modified: 26 Jun 2025

    A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, and Exynos 2400 that involves a time-of-check to time-of-use (TOCTOU) race condition, which can lead to a Denial of Service.

    Published: 9 Jul 2024
    4.4
    Medium

    CVE-2024-27362

    Last Modified: 20 Mar 2025

    A vulnerability was discovered in Samsung Mobile Processors Exynos 1280, Exynos 2200, Exynos 1330, Exynos 1380, and Exynos 2400 where they do not properly check the length of the data, which can lead to a Information disclosure.

    Published: 9 Jul 2024
    6.7
    Medium

    CVE-2024-27385

    Last Modified: 26 Jun 2025

    A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for rx coming from userspace, which can lead to heap overwrite.

    Published: 9 Jul 2024
    5.3
    Medium

    CVE-2024-28067

    Last Modified: 21 Nov 2024

    A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode of packets going to the victim, enabling the attacker to send messages to the victim in plaintext.

    Published: 9 Jul 2024
    7.5
    High

    CVE-2024-30105

    Last Modified: 9 Dec 2025

    .NET and Visual Studio Denial of Service Vulnerability

    Published: 9 Jul 2024
    6.2
    Medium

    CVE-2024-31957

    Last Modified: 25 Mar 2025

    A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-36526

    Last Modified: 17 Jun 2025

    ZKTeco ZKBio CVSecurity v6.1.1 was discovered to contain a hardcoded cryptographic key.

    Published: 9 Jul 2024
    7.5
    High

    CVE-2024-36676

    Last Modified: 15 Apr 2026

    Incorrect access control in BookStack before v24.05.1 allows attackers to confirm existing system users and perform targeted notification email DoS via public facing forms.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-6602

    Last Modified: 3 Nov 2025

    A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-37830

    Last Modified: 21 Nov 2024

    An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.

    Published: 9 Jul 2024
    5.9
    Medium

    CVE-2024-37865

    Last Modified: 21 Nov 2024

    An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.

    Published: 9 Jul 2024
    8.1
    High

    CVE-2024-37872

    Last Modified: 14 May 2025

    SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-37873

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in view_payslip.php in Itsourcecode Payroll Management System Project In PHP With Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 Jul 2024
    7.3
    High

    CVE-2024-38081

    Last Modified: 9 Dec 2025

    .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-38959

    Last Modified: 21 Oct 2025

    Cross Site Scripting vulnerability in Creativeitem Academy LMS Learning Management System v.6.8.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the string parameter.

    Published: 9 Jul 2024
    4.9
    Medium

    CVE-2024-38970

    Last Modified: 20 Mar 2025

    vaeThink 1.0.2 is vulnerable to Information Disclosure via the system backend,access management administrator function.

    Published: 9 Jul 2024
    5.4
    Medium

    CVE-2024-38971

    Last Modified: 27 Mar 2025

    vaeThink 1.0.2 is vulnerable to stored Cross Site Scripting (XSS) in the system backend.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-38972

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/add/.

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-39063

    Last Modified: 30 Jan 2026

    Lime Survey <= 6.5.12 is vulnerable to Cross Site Request Forgery (CSRF). The YII_CSRF_TOKEN is only checked when passed in the body of POST requests, but the same check isn't performed in the equivalent GET requests.

    Published: 9 Jul 2024
    7.8
    High

    CVE-2024-39069

    Last Modified: 15 Apr 2026

    An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hijacking attack.

    Published: 9 Jul 2024
    5.5
    Medium

    CVE-2024-39118

    Last Modified: 27 Aug 2025

    Mommy Heather Advanced Backups up to v3.5.3 allows attackers to write arbitrary files via restoring a crafted back up.

    Published: 9 Jul 2024
    9.8
    Critical

    CVE-2024-39171

    Last Modified: 21 Nov 2024

    Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.

    Published: 9 Jul 2024
    7.1
    High

    CVE-2024-39487

    Last Modified: 3 Nov 2025

    In the Linux kernel, the following vulnerability has been resolved: bonding: Fix out-of-bounds read in bond_option_arp_ip_targets_set() In function bond_option_arp_ip_targets_set(), if newval->string is an empty string, newval->string+1 will point to the byte after the string, causing an out-of-bound read. BUG: KASAN: slab-out-of-bounds in strlen+0x7d/0xa0 lib/string.c:418 Read of size 1 at addr ffff8881119c4781 by task syz-executor665/8107 CPU: 1 PID: 8107 Comm: syz-executor665 Not tainted 6.7.0-rc7 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 Call Trace: <TASK> __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0xd9/0x150 lib/dump_stack.c:106 print_address_description mm/kasan/report.c:364 [inline] print_report+0xc1/0x5e0 mm/kasan/report.c:475 kasan_report+0xbe/0xf0 mm/kasan/report.c:588 strlen+0x7d/0xa0 lib/string.c:418 __fortify_strlen include/linux/fortify-string.h:210 [inline] in4_pton+0xa3/0x3f0 net/core/utils.c:130 bond_option_arp_ip_targets_set+0xc2/0x910 drivers/net/bonding/bond_options.c:1201 __bond_opt_set+0x2a4/0x1030 drivers/net/bonding/bond_options.c:767 __bond_opt_set_notify+0x48/0x150 drivers/net/bonding/bond_options.c:792 bond_opt_tryset_rtnl+0xda/0x160 drivers/net/bonding/bond_options.c:817 bonding_sysfs_store_option+0xa1/0x120 drivers/net/bonding/bond_sysfs.c:156 dev_attr_store+0x54/0x80 drivers/base/core.c:2366 sysfs_kf_write+0x114/0x170 fs/sysfs/file.c:136 kernfs_fop_write_iter+0x337/0x500 fs/kernfs/file.c:334 call_write_iter include/linux/fs.h:2020 [inline] new_sync_write fs/read_write.c:491 [inline] vfs_write+0x96a/0xd80 fs/read_write.c:584 ksys_write+0x122/0x250 fs/read_write.c:637 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0x40/0x110 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x63/0x6b ---[ end trace ]--- Fix it by adding a check of string length before using it.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40728

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-server-ports/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40729

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/add/.

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-40034

    Last Modified: 21 Nov 2024

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=del

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-40036

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=add&nohrefStr=close

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-40037

    Last Modified: 21 Nov 2024

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=del

    Published: 9 Jul 2024
    5.3
    Medium

    CVE-2024-40038

    Last Modified: 15 Apr 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=rev

    Published: 9 Jul 2024
    8.8
    High

    CVE-2024-40039

    Last Modified: 13 Mar 2025

    idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userGroup_deal.php?mudi=del

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40726

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-ports/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40727

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-server-ports/add/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40730

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/interfaces/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40731

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/rear-ports/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40732

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/rear-ports/add/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40733

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/front-ports/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40734

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/front-ports/add/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40735

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-outlets/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40736

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-outlets/add.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40738

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/console-ports/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40739

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-feeds/add.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40740

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter at /dcim/power-feeds/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40741

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit ID parameter at /circuits/circuits/{id}/edit/.

    Published: 9 Jul 2024
    6.1
    Medium

    CVE-2024-40742

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit ID parameter at /circuits/circuits/add.

    Published: 9 Jul 2024